CVE-2026-86246: insecure default configuration in Apache Software Foundation Apache Tomcat Native

Remote, unauthenticated attackers can encounter insecure default TLS behavior in Apache Tomcat Native (CVE-2026-86246), which enables unsafe options by default. Affected releases include branch 2.x: 2.0.0 through 2.0.15 and branch 1.x: 1.3.0 through 1.3.8. The issue requires network access and no authentication, and it may allow attackers to weaken or bypass recommended TLS protections because several insecure options are enabled out of the box.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.1CRITICAL
EPSS
0.0028
CWE
CWE-1188
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as high priority: the vulnerability is remotely reachable without authentication (CVSS vector AV:N/PR:N/UI:N), so immediately limit exposure of Tomcat Native instances and apply vendor guidance as available.

What is CVE-2026-86246?

Remote, unauthenticated attackers can encounter insecure default TLS behavior in Apache Tomcat Native (CVE-2026-86246), which enables unsafe options by default. Affected releases include branch 2.x: 2.0.0 through 2.0.15 and branch 1.x: 1.3.0 through 1.3.8. The issue requires network access and no authentication, and it may allow attackers to weaken or bypass recommended TLS protections because several insecure options are enabled out of the box.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Which versions of Apache Software Foundation Apache Tomcat Native are affected?

BRANCHAFFECTEDFIXED
2.x2.0.0 – 2.0.15
1.x1.3.0 – 1.3.8

Is CVE-2026-86246 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-86246

  1. If possible, remove or disable Apache Tomcat Native where it is not required.
  2. Restrict network exposure: firewall or limit listeners so Tomcat Native is not internet-facing.
  3. Harden TLS settings by disabling insecure options such as client renegotiation and other non-recommended cipher/extension defaults where configurable.
  4. Monitor TLS-related logs and connections for unexpected renegotiation or abnormal handshake parameters and follow vendor advisories for updates.

Frequently asked questions

Is CVE-2026-86246 being actively exploited?

There are no public reports of active exploitation of CVE-2026-86246 as of 2026-09-30.

Which Apache Tomcat Native versions are affected by CVE-2026-86246?

Apache Tomcat Native versions 2.0.0 through 2.0.15 (branch 2.x) and 1.3.0 through 1.3.8 (branch 1.x) are listed as affected.

Is there a patch for CVE-2026-86246?

No patch was reported available as of 2026-09-30; administrators should follow vendor advisories and apply fixes when the Apache Software Foundation publishes them.

Does CVE-2026-86246 require authentication?

No; the vulnerability can be reached over the network without authentication, meaning Apache Tomcat Native instances exposed to untrusted networks are at greater risk.

References